Advanced Plus Security Tume Security Configuration 2018

Last updated
Oct 29, 2018
Windows Edition
Enterprise
Security updates
Allow security updates
User Access Control
Always notify
Real-time security
ESET Internet Security 12 - Firewall off
OSArmor 1.4
Windows Firewall Control 5.4
Sandboxie 5.26 Lifetime
SysHardener 1.5
KeyScrambler Premium 3.12
Firewall security
Periodic malware scanners
Hitman Pro
Winja
Malware sample testing
Browser(s) and extensions
Vivaldi 2.1 64-bit
Maintenance tools
PatchMyPC
VeraCrypt (Complete encryption with AES & Whirlpool)
PrivaZer Donors Edition
Revo Uninstaller Pro v4
Cryptomator
O&O Shutdown + My own configuration to disable all telemetry.
Telemetry level: 0 - Security [Enterprise only]
File and Photo backup
Sync.com -> Sync to Cloud
System recovery
Macrium Reflect 7.1 Home -> External HDD
Computer specs
https://malwaretips.com/threads/tumes-pc.86768/

Arequire

Level 29
Verified
Top Poster
Content Creator
Feb 10, 2017
1,823
A few suggestions:
  • Set UAC to Always Notify
  • Enable Smartscreen system-wide
As @Syafiq said, you can put OSArmor in the real-time protection bracket.

Why use SWRIron instead of Chrome/Chromium?

Why use uMatrix alongside Adguard? If used correctly uMatrix makes any ad blocker completely irrelevant.
 
Last edited:

Tume

Level 2
Thread author
Verified
Mar 30, 2018
68
A few suggestions:
  • Set UAC to Always Notify
  • Enable Smartscreen system-wide
As @Syafiq said, you can put OSArmor in the real-time protection bracket.

Why use SWRIron instead of Chrome/Chromium?

Why use uMatrix alongside Adguard? If used correctly uMatrix makes any ad blocker completely irrelevant.

I don't want use SmartScreen at all, because I'm little bit paranoid what comes to telemetry etc :).

SRWare Iron doesn't share any my info with Google like Chrome do.

uMatrix is script blocker to me. Specifically Javascript. Adguard blocks ads etc.

And thank to guide me, I have to check what new OSArmor 1.4 provide then.
 

Arequire

Level 29
Verified
Top Poster
Content Creator
Feb 10, 2017
1,823
I don't want use SmartScreen at all, because I'm little bit paranoid what comes to telemetry etc :).
I'll do some research into this and try to find out what it sends exactly. If I had to guess it'd be your IP address and the hash of any executables downloaded to check against their white/blacklist.
SRWare Iron doesn't share any my info with Google like Chrome do.
Sadly there's two big issues with SWRIron:
  1. It's slow to update, so you're missing security patches that have been available to Chrome users for weeks or even months
  2. It's claims about privacy are completely overblown. Most of the information it claims to protect against sending to Google can actually be stopped in Chrome by simply disabling all the options in the "Privacy and security" section. Also it'll be connecting to Google's servers every time you launch it as it has to check for updates for the extensions (assuming you didn't unpack them yourself) which sends your IP address along with it
 

LDogg

Level 33
Verified
Top Poster
Well-known
May 4, 2018
2,261
SRWare Iron maybe a hit and miss in what they state about stopping Google Chromium privacy concerns.

Things to add:
  • ZAM Free
  • Maybe Emsisoft Emergency Kit
  • Privacy Possum, features on this extension that are not available on the ones you currently have.
  • Smartscreen turned on, Win 10 spying could be downplayed.
Apart from things listed, very good config.

~LDogg
 

Tume

Level 2
Thread author
Verified
Mar 30, 2018
68
I'll do some research into this and try to find out what it sends exactly. If I had to guess it'd be your IP address and the hash of any executables downloaded to check against their white/blacklist.

Sadly there's two big issues with SWRIron:
  1. It's slow to update, so you're missing security patches that have been available to Chrome users for weeks or even months
  2. It's claims about privacy are completely overblown. Most of the information it claims to protect against sending to Google can actually be stopped in Chrome by simply disabling all the options in the "Privacy and security" section. Also it'll be connecting to Google's servers every time you launch it as it has to check for updates for the extensions (assuming you didn't unpack them yourself) which sends your IP address along with it

Maybe I would change browser to Vivaldi.

Why Smartscreen disabled?

As I said earlier: "I don't want use SmartScreen at all, because I'm little bit paranoid what comes to telemetry etc "

"If you choose to use Windows SmartScreen to check downloaded files, Windows sends information to the SmartScreen online service This information might include a file name, file identifier (“hash”), and digital certificate information along with standard PC information and the Windows SmartScreen filter version number. "

Basically, I don't want windows or anyone sniff my files at all.

SRWare Iron maybe a hit and miss in what they state about stopping Google Chromium privacy concerns.

Why you think so?
 

Arequire

Level 29
Verified
Top Poster
Content Creator
Feb 10, 2017
1,823
Why you think so?
Let's go through their privacy comparison list and you'll see:

  • Installation-ID
A copy of Google Chrome includes a generated installation number which will be sent to Google after the installation and the first usage. It gets deleted when Chrome checks first time for updates.If Chrome is received as part of a promotional campaign, it may generate a unique promotion number which is sent to Google on the first run and first use of Google Chrome.
Pretty much every software does this, and as you'll note it states "it gets deleted when Chrome checks first time for updates."

  • Suggest
Depending on the configuration, each time you put something in the address line,this information is sent to Google to provide suggestions.
This can be disabled by turning off "Use a prediction service to help complete searches and URLs typed in the address bar" in Chrome.

  • Alternate Error Pages
Depending on the configuration, if you have typed a false address in the adress bar, this is sent to Google and you get an error message from Google's servers.
This can be disabled by turning off "Use a web service to help resolve navigation errors" in Chrome.

  • Error Reporting
Depending on the configuration, details about crashes or failures are sent Google's servers.
This can be disabled by turning off "Automatically send usage statistics and crash reports to Google" in Chrome. Also note that you're given the option to disable this at the point of Chrome's installation.

  • RLZ-Tracking
This Chrome-function transmits information in encoded form to Google, for example, when and where Chrome has been downloaded.
This only exists if you download Chrome from a third-party source (not their official site).

  • Google Updater
Chrome installs a updater, which loads at every Windows in background.
Not a privacy feature.

  • URL-Tracker
Calls depending on the configuration five seconds after launch the Google homepage opens in background
Misleading name for it and non-existent when using any other search engine besides Google.

  • Adblocker
Chrome doesn't have an built-in adblocker
It does and it's turned-on by default. Only blocks ads that fit the criteria of "annoying" set by the Coalition for Better Ads.

  • User-Agent
The User-Agent in Chrome is only be changeable with parameters over a link or command, which isn't really ideal for permanent usage.
Can be easily changed by an extension.

  • Preview-Thumbs
Chrome only has 8 preview thumbs on the "NewTab"-Page
Not a privacy feature.

I'm not going to tell you to stop using it; if you still feel more private using it then more power to you. Just know that their privacy claims are mostly scaremongering that can be easily applied in Chrome too and their browser is pretty much always out-of-date in comparison.
 
Last edited:

Tume

Level 2
Thread author
Verified
Mar 30, 2018
68
Little bit changelog:

SRWare Iron -> Vivaldi 1.15 64-bit
Added extension: Privacy Possum
Added more info for VeraCrypt too.
UAC -> Always Notify
 
Last edited:

Tume

Level 2
Thread author
Verified
Mar 30, 2018
68
Changelog 1.9.2018:

Win:
+ Windows 1709 -> 1803

Security:
+ Forticlient 6.0 -> Added Web Filter
+ OSArmor 1.3 -> Update 1.4
+ WFC 5.1 -> Update WFC 5.3
+ Sandboxie 5.26 Lifetime (Using to Mailbird)
+ Virustotal Uploader

Backup:
+ Sync.com -> Sync to Cloud


Removed:
- Privacy Possum
- WrbRTC Control
 
  • Like
Reactions: harlan4096

LDogg

Level 33
Verified
Top Poster
Well-known
May 4, 2018
2,261
How are you finding Forticlient by the way?

~LDogg
 

Tume

Level 2
Thread author
Verified
Mar 30, 2018
68
It's fine. As you have Forticlient, how is the software performing in your opinion?

~LDogg

Ahaa, now I understand!

I love it. Very light, powerful and large configurations, so you can make it how strict you want. I also like that you can turn off all telemetry.

Web Filter is the best one what I ever seen :)
 

Tume

Level 2
Thread author
Verified
Mar 30, 2018
68
Changelog 15.9:

Security:
+ SysHardener 1.5
+ WFC 5.3 -> Update WFC 5.4 (But blocked itself to send any telemetry)

Utilities:
+ Revo Uninstaller Pro v3 -> v4
 
Last edited:

HarborFront

Level 71
Verified
Top Poster
Content Creator
Oct 9, 2016
6,033
I don't want use SmartScreen at all, because I'm little bit paranoid what comes to telemetry etc :).

SRWare Iron doesn't share any my info with Google like Chrome do.

uMatrix is script blocker to me. Specifically Javascript. Adguard blocks ads etc.

And thank to guide me, I have to check what new OSArmor 1.4 provide then.
SRWare Iron is not 'ungoogled'

Ungoogled Chromium is.
 
  • Like
Reactions: oldschool

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top